3 ms·
I had a really bad experience with the bitwarden cli. I believe it was `bw list` that I ran, assuming it would list the names of all my passwords, but too my s
by 1024kb 5mo ago
I had a really bad experience with the bitwarden cli. I believe it was `bw list` that I ran, assuming it would list the names of all my passwords, but too my surprise, it listed everything, including passwords and current totp codes. That's not the worst of it though. For some reason, when I ssh'ed into one of my servers and opened tmux, where I keep a weechat irc client running, I noticed that the entire content of the bw command was accessible from within the weechat text input field history. I have no idea how this happened, but it was quite terrifying. The issue persisted across tmux and weechat sessions, and only a reboot of the server would solve the problem.
I promptly removed the bw cli programme after that, and I definitely won't be installing it again.
I use ghostty if it matters.
- trinsic2 5mo agoWow. Thats crazy. Is there an extension for bwcli in weechat? BTW I didnt even know BW had a cli until now. I use keepass locally.
- 1024kb 5mo agoI don't know, I use a vanilla weechat setup
- harshreality 5mo agoIt's crazy because it's not default bw behavior, or even any bw behavior... I don't use the cli, but I don't see any built-in capacity to copy bw output to the clipboard. (In the UNIX way, you'd normally pipe it to a clipboard utility if you wanted it copied, and then the security consequences are on you.) They probably caused it themselves, somehow, and then blamed bitwarden. Note in the original comment they aren't even entirely sure what the command was, and they weren't familiar with it or they wouldn't have been surprised by its output... so how can they be sure what else they did between that command and the weechat thing? If the terminal or tmux fed terminal history into weechat, that's also not bw's problem.
- pprotas 5mo ago`bw list` shows plaintext credentials in the CLI https://bitwarden.com/help/cli/#list https://bitwarden.com/help/cli/#list I know this because I had the same surprised reaction
- martin- 5mo agoNo one is disputing that part. It's the "copied into clipboard automatically" part that sounds implausible.
- deleted 5mo ago[deleted]
- nicce 5mo agoI thought that CLI would be efficent when I looked for using it and then I figured it is JavaScript
- rvz 5mo agoExactly. That is the problem. There is a time and place for where it makes sense and a password manager CLI written in TypeScript importing hundreds of third-party packages is a direct red flag. It is a frequent occurrence. We have seen it happen with Axios which is one of the biggest supply chain attacks on the Javascript / Typescript ecosystem and it makes no sense to build sensitive tools with that.
- lxgr 5mo ago> importing hundreds of third-party packages But how else are you going to check if a number is even or odd? Remember, the ONLY design goal is not repeating yourself (or in fact anything anyone has ever thought of implementing).
- dannyw 5mo agoThat’s a serious red flag. I’m concerned and I don’t think it shows a security first culture.
- stvnbn 5mo agoI love how the first comment is a complain having nothing to do with the actual subjec
- cobolcomesback 5mo agoNot to mention utter nonsense. There’s no possible way that BW CLI somehow injected command history into a remote server. That was 100% something the GP did, a bug in their terminal, or a config they have with ssh/tmux, not Bitwarden.
- reactordev 5mo agothat's our future... with AI. Engineers that don't know the difference between client-side convenience and server-side injection, how to configure `php.ini`, or that no synchronized password manager is safe. While the OAuth scope is `*`, and CORS is what you drink on the weekend.
- Sohcahtoa82 5mo agoCan someone explain why people struggle with CORS? The full strength of the SOP applies by default. CORS is an insecurity feature that relaxes the SOP. Unless you need to relax the SOP, you shouldn't be enabling CORS, meaning you shouldn't be sending an Access-Control-Allow-Origin header at all. If your front-end at www.example.com makes calls to api.example.com, then it's simple enough to just add www.example.com to CORS.
- 12_throw_away 5mo agoIME, CORS is pretty straightforward in prod but can be a huge pain in dev environments, so you end up with lots of little hacks to get your dev environments working (and then one of those hacks leaks back into prod and now you have CORS problems in prod).
- reactordev 5mo ago
- deleted 5mo ago[deleted]
- saadn92 5mo ago[dead]